What is CVE-2026-75626?
SpiderFoot HMI vulnerability. Correlation titles built from external scan data sources like server banners and metadata are not HTML-escaped. Attackers can inject malicious HTML elements with event handlers that execute scripts in the operator's browser when the correlations view is opened. Upgrading to the latest version of SpiderFoot is recommended.
Azərbaycanca: SpiderFoot HMI (Human-Machine Interface) zəifliyi. Xarici skan mənbələrindən, o cümlədən server bannerləri və metadatadan yaradılan korrelyasiya başlıqlarında HTML escape edilmir. Təcavüzkar, operatorun brauzerində korrelyasiya görünüşü açıldıqda icra olunan zərərli HTML elementlər (event handler ilə) daxil edə bilər. Təsirə məruz qalmamaq üçün SpiderFoot-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
What vulnerability is caused by correlation titles in SpiderFoot HMI?
Correlation titles in SpiderFoot HMI, built from external scan data sources like server banners and metadata, are not HTML-escaped. This allows attackers to inject malicious HTML elements that execute scripts in the operator's browser when the correlations view is opened.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.